Loading HuntDB...

SQL Injection in report_xml.php through countryFilter[] parameter

Critical
V
Valve
Submitted None

Team Summary

Official summary from Valve

An unvalidated parameter on an partner reporting page (report_xml.php) could be used to read certain SQL data from a single backing database.

Reported by moskowsky

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$25000.00

Submitted

Weakness

SQL Injection